Where the filtering happens
Protection that runs on your own server is not protection. By the time a flood reaches the machine it has already crossed your uplink, and a saturated uplink drops legitimate traffic just as effectively as a saturated CPU does.
Virtbase servers sit behind aurologic GmbH's filtering, which is upstream of the network the machine is on. Attack traffic is scrubbed before it arrives, so your uplink never carries it and your server never sees it.
That also means there is nothing for you to run, tune or keep patched. There is no agent on the machine, no rule to write, and no threshold to guess.